CB-WP-0014-T01/T02: execute the JavaScript — and find AM-4b blind
ADR-0009: embed quick-js; node is refused. Measured marginal cost against the dev-toolchain graph, under the positive control: boa_engine 896,410 rquickjs 69,985 quick-js 11,434 node 0 <- and that zero is the problem ADR-0007 D3's acquisition rule biting its author. CI runs on rust:1.97, which has no node, so the test would make our build fetch a JS runtime of tens of millions of unaudited lines while scoring zero on the only instrument that governs dependencies. A browser is exempt because a developer has one regardless of us; a CI-installed runtime is not. The loop is now closed: the real server serves the real page, QuickJS runs that page's own scripts, the gesture goes over a real socket, and the seat's Choice comes back. Before this, every link was tested and the chain was not — a page whose JavaScript sent something else entirely would have passed everything. Three controls, each red for its stated reason: the JS posting a command name instead of ids, the gesture not being delivered (EXPECT-VACUOUS), and the token stripped from the endpoint. A wrong assertion worth keeping: the first draft required the body not to contain "attack". It legitimately does — action-attack is the id of an element a finger landed on. An element may name an action; that is not the page deciding. The real test is the shape: exactly two fields, down and up, carrying two ids and nothing derived from them. AND the ADR's own cost argument was wrong. It claimed 35% of AM-4b's headroom; after landing AM-4b did not move at all. It measures games-ground --edges normal — one package, no dev edges. Measured, the workspace including dev edges is 725,258 lines against AM-4b's 317,021: 408,237 uncounted, MORE THAN THE TARGET ITSELF (criterion, clap, ciborium, quick-js). The decision stands on the acquisition rule; the affordability argument is withdrawn. Third defect in the AM-4 family. Also fixed structurally rather than by raising a limit: `make status` had grown past its 40-line readability gate as workplans accumulated. Closed workplans now collapse to one line, so the report is fixed-size. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
4c930fac32
commit
55212d7e0f
9 changed files with 599 additions and 8 deletions
|
|
@ -370,4 +370,60 @@ mod tests {
|
|||
);
|
||||
assert!(replies[1].contains("200 OK"));
|
||||
}
|
||||
|
||||
/// **The loop, closed.** The real server serves the real page; a real
|
||||
/// JavaScript engine runs the page's own script and produces a pointer
|
||||
/// gesture; what it produces goes over a real socket; and the seat's
|
||||
/// choice comes back.
|
||||
///
|
||||
/// Before ADR-0009 every link in that chain was tested and the chain
|
||||
/// was not. The page was asserted against as a parsed document and the
|
||||
/// socket was driven by synthetic HTTP that this test suite wrote
|
||||
/// itself — so a page whose JavaScript sent something else entirely
|
||||
/// would have passed everything.
|
||||
#[test]
|
||||
fn a_gesture_in_javascript_becomes_a_move_in_the_game() {
|
||||
let server = Server::bind(0).expect("bind");
|
||||
let port = server.listener.local_addr().unwrap().port();
|
||||
let token = server.url().rsplit("t=").next().unwrap().to_string();
|
||||
|
||||
let tok = token.clone();
|
||||
let client = std::thread::spawn(move || {
|
||||
let token = tok;
|
||||
// 1. fetch the page the server actually serves
|
||||
let mut s = TcpStream::connect(("127.0.0.1", port)).expect("connect");
|
||||
s.write_all(get(&token).as_bytes()).expect("write");
|
||||
let mut page = String::new();
|
||||
let _ = s.read_to_string(&mut page);
|
||||
assert!(page.contains("200 OK"), "{page}");
|
||||
|
||||
// 2. run ITS script, in a real engine, with a real gesture
|
||||
let posts = cb_render_html::jsrun::gesture(&page, "action-ground", "table")
|
||||
.expect("the served page's script runs");
|
||||
assert_eq!(posts.len(), 1, "{posts:?}");
|
||||
|
||||
// 3. send exactly what the JavaScript produced — not what this
|
||||
// test thinks it should have produced
|
||||
let mut s = TcpStream::connect(("127.0.0.1", port)).expect("connect");
|
||||
s.write_all(post(&token, &posts[0].body).as_bytes())
|
||||
.expect("write");
|
||||
let mut reply = String::new();
|
||||
let _ = s.read_to_string(&mut reply);
|
||||
(posts[0].clone(), reply)
|
||||
});
|
||||
|
||||
let choice = server
|
||||
.next_choice(&state(), PlayerId(0), &ground_only(), false)
|
||||
.expect("a choice");
|
||||
assert_eq!(choice, Choice::Command(0));
|
||||
|
||||
let (posted, reply) = client.join().expect("client thread");
|
||||
assert_eq!(posted.body, "down=action-ground&up=table");
|
||||
// The endpoint the JS used carries the server's own token, which
|
||||
// the page cannot mint — so this also proves the token round-trips
|
||||
// through the emitted document.
|
||||
assert!(posted.url.contains(&token), "{}", posted.url);
|
||||
assert!(reply.contains("200 OK"), "{reply}");
|
||||
assert!(server.refusals().is_empty(), "{:?}", server.refusals());
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue